Hearing Device Memory Security via Unique Key Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hearing devices, particularly hearing aids, face challenges in ensuring that firmware updates are authorized and compatible with the specific device, preventing unauthorized upgrades from lower-priced to higher-priced configurations, which could compromise functionality and user experience.

Innovation Solution

A hearing device with a memory unit comprising a non-static and static section, where the static section stores a unique key used by a verifier to authenticate firmware updates, ensuring that only compatible data is stored and preventing unauthorized changes by discarding data that does not meet the verification criterion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hearing devices are made programmable with online update capability, then device functionality and adaptability are improved, but security risks and vulnerability to unauthorized updates increase

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-storing a unique key in the static memory section during device manufacturing. This key is prepared in advance to authenticate any future firmware updates, ensuring that before any online programming occurs, the device already has the necessary security credential to verify the authenticity of incoming data, thus preventing unauthorized updates while maintaining programmability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a verification mechanism as an intermediary between the received firmware data and the device's memory system. The verifier checks whether the received data contains a second key that matches the unique key stored in static memory before allowing any update to occur. This intermediary verification step blocks unauthorized updates while permitting legitimate firmware updates, resolving the contradiction between adaptability and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If firmware updates are allowed without verification, then ease of operation is improved, but device integrity and compatibility are compromised

Engineering Contradiction:
Improvefirmware update processVSAvoiddevice integrity
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The patent implements self-service by enabling the hearing device to automatically verify the authenticity of received firmware updates using its stored unique key. The device's internal verifier autonomously checks whether the second key in received data matches the unique key in static memory, and only allows updates when verification succeeds. This automatic self-verification maintains ease of operation while protecting device integrity, as no manual intervention is needed and unauthorized updates are automatically blocked

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10841714B2Programmable hearing device and method of programming a hearing device
Publication Date: 2020.11.17 OTICON
  • US10841714B2 patent drawing
  • US10841714B2 patent drawing

AI summary

The invention relates to a hearing device that comprises a data interface for receiving data and a memory unit for storing data. The memory unit comprises a non-static section and a static section. The static section comprises a unique key that is unique for the specific hearing device. The hearing device further comprises a verifier that is configured to process the unique key and a second key contained in first type data received via the data interface in order to determine whether the second key needs a verification criterion with respect to the unique key. The verifier is further configured to discard received first type data in the non-static section of the memory unit if the second key contained in received data does not meet the verification criterion with respect to the unique key stored in the static section of the memory unit.